microsoft
3,712 known vulnerabilities affecting microsoft products.
Products
windows_server_2019 1452
windows_server_2016 1310
windows_server_2022 1272
windows_server_2025 1131
windows_10_1809 1131
windows_11_24h2 1111
windows_11_25h2 1081
windows_10_22h2 1066
windows_10_21h2 1061
windows_11_26h1 1009
windows 990
windows_10_1607 980
windows_server_2012 977
windows_11_23h2 761
windows_10 343
windows_server_2008 326
365_apps 277
office_2021 225
office_2024 225
office_2019 217
windows_8.1 192
microsoft_365 185
windows_rt_8.1 170
windows_7 169
Vulnerabilities by priority
| CVE | Priority | EPSS | CVSS | KEV | What |
|---|---|---|---|---|---|
| CVE-2020-17163 | Medium | 0.6% | 7.8 | Visual Studio Code Python Extension Remote Code Execution Vulnerability | |
| CVE-2021-33762 | Medium | 0.6% | 7.0 | Azure CycleCloud Elevation of Privilege Vulnerability | |
| CVE-2026-42987 | Medium | 0.6% | 8.1 | Use after free in Windows Deployment Services allows an unauthorized attacker to… | |
| CVE-2026-70326 | Medium | 0.6% | 8.8 | Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an auth… | |
| CVE-2026-56160 | Medium | 0.6% | 9.1 | Improper authorization in Azure Red Hat OpenShift (ARO) allows an authorized att… | |
| CVE-2026-57105 | Medium | 0.6% | 8.0 | Improper neutralization of input during web page generation ('cross-site scripti… | |
| CVE-2026-26147 | Medium | 0.6% | 7.7 | Improper input validation in Azure Compute Gallery allows an authorized attacker… | |
| CVE-2026-62819 | Medium | 0.6% | 8.1 | Remote Code Execution in Windows Routing and Remote Access Service (RRAS) allows… | |
| CVE-2026-23652 | Medium | 0.6% | 10.0 | Improper neutralization of special elements used in a command ('command injectio… | |
| CVE-2023-36904 | Medium | 0.6% | 7.8 | Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability | |
| CVE-2024-38188 | Medium | 0.6% | 7.1 | Azure Network Watcher VM Agent Elevation of Privilege Vulnerability | |
| CVE-2026-50683 | Medium | 0.6% | 8.0 | Heap-based buffer overflow in Windows DHCP Server allows an authorized attacker … | |
| CVE-2026-69876 | Medium | 0.6% | 8.0 | Use after free in Windows DHCP Server allows an authorized attacker to execute c… | |
| CVE-2026-63093 | Medium | 0.6% | 8.8 | Cursor for Windows version 3.2.16 contains a binary planting vulnerability that … | |
| CVE-2026-66818 | Medium | 0.6% | 8.8 | Improper privilege management in SQL Server allows an authorized attacker to ele… | |
| CVE-2026-71328 | Medium | 0.6% | 8.8 | Heap-based buffer overflow in Visual Studio allows an unauthorized attacker to e… | |
| CVE-2026-73016 | Medium | 0.6% | 8.8 | Heap-based buffer overflow in Microsoft Graphics Component allows an unauthorize… | |
| CVE-2026-8505 | Medium | 0.6% | 9.8 | IBM Langflow OSS 1.0.0 through 1.10.0 has a vulnerability in Langflow's webhook … | |
| CVE-2026-56623 | Medium | 0.6% | 7.1 | Path traversal on Windows in Apache MINA SSHD component sshd-git. Apache MINA SS… | |
| CVE-2026-69502 | Medium | 0.6% | 10.0 | Server-side request forgery (ssrf) in Azure SQL Database allows an unauthorized … | |
| CVE-2026-69519 | Medium | 0.6% | 8.6 | Observable response discrepancy in Azure Stack HCI allows an unauthorized attack… | |
| CVE-2026-50398 | Medium | 0.6% | 8.8 | Concurrent execution using shared resource with improper synchronization ('race … | |
| CVE-2026-50414 | Medium | 0.6% | 7.5 | Concurrent execution using shared resource with improper synchronization ('race … | |
| CVE-2026-58608 | Medium | 0.6% | 8.8 | Concurrent execution using shared resource with improper synchronization ('race … | |
| CVE-2024-38246 | Medium | 0.6% | 7.0 | Win32k Elevation of Privilege Vulnerability | |
| CVE-2026-65679 | Medium | 0.6% | 8.1 | Heap-based buffer overflow in Windows iSCSI Target Service allows an unauthorize… | |
| CVE-2024-38248 | Medium | 0.6% | 7.0 | Windows Storage Elevation of Privilege Vulnerability | |
| CVE-2026-65770 | Medium | 0.6% | 10.0 | Improper neutralization of argument delimiters in a command ('argument injection… | |
| CVE-2021-34460 | Medium | 0.6% | 7.8 | Windows Storage Spaces Controller Elevation of Privilege Vulnerability | |
| CVE-2021-34477 | Medium | 0.6% | 7.8 | Visual Studio Code .NET Runtime Elevation of Privilege Vulnerability | |
| CVE-2021-34488 | Medium | 0.6% | 7.8 | Windows Console Driver Elevation of Privilege Vulnerability | |
| CVE-2021-34511 | Medium | 0.6% | 7.8 | Windows Installer Elevation of Privilege Vulnerability | |
| CVE-2026-8992 | Medium | 0.6% | 8.8 | An improper certificate validation vulnerability in Ivanti Secure Access Client … | |
| CVE-2026-50481 | Medium | 0.6% | 9.9 | Modification of assumed-immutable data (maid) in Azure Active Directory allows a… | |
| CVE-2026-50528 | Medium | 0.6% | 8.2 | Incorrect authorization in .NET allows an unauthorized attacker to bypass a secu… | |
| CVE-2026-20864 | Medium | 0.6% | 7.8 | Heap-based buffer overflow in Connected Devices Platform Service (Cdpsvc) allows… | |
| CVE-2026-62889 | Medium | 0.6% | 8.1 | Double free in Windows Secure Socket Tunneling Protocol (SSTP) allows an unautho… | |
| CVE-2026-69400 | Medium | 0.6% | 9.6 | Improper limitation of a pathname to a restricted directory ('path traversal') i… | |
| CVE-2026-7667 | Medium | 0.6% | 8.8 | IBM Langflow OSS 1.0.0 through 1.10.0 allows an authenticated attacker to create… | |
| CVE-2026-8859 | Medium | 0.6% | 9.9 | IBM Langflow OSS 1.0.0 through 1.10.0 Langflow could allow an attacker to write … | |
| CVE-2026-47634 | Medium | 0.6% | 7.3 | Improper neutralization of special elements in output used by a downstream compo… | |
| CVE-2026-68834 | Medium | 0.6% | 8.0 | Stack-based buffer overflow in Windows NTFS allows an authorized attacker to ele… | |
| CVE-2021-34456 | Medium | 0.6% | 7.8 | Windows Remote Access Connection Manager Elevation of Privilege Vulnerability | |
| CVE-2026-69414 | Medium | 0.6% | 7.8 | Microsoft is aware of an elevation of privilege in the Microsoft Malware Protect… | |
| CVE-2026-45644 | Medium | 0.6% | 8.0 | Improper neutralization of input during web page generation ('cross-site scripti… | |
| CVE-2026-69285 | Medium | 0.6% | 8.8 | Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker t… | |
| CVE-2026-73013 | Medium | 0.6% | 8.8 | Heap-based buffer overflow in Windows Imaging Component allows an unauthorized a… | |
| CVE-2026-73023 | Medium | 0.6% | 8.8 | Heap-based buffer overflow in Windows Imaging Component allows an unauthorized a… | |
| CVE-2026-77495 | Medium | 0.6% | 8.8 | Heap-based buffer overflow in Windows Imaging Component allows an unauthorized a… | |
| CVE-2026-48303 | Medium | 0.6% | 10.0 | Adobe Campaign Classic (ACC) versions 7.4.3 build 9394 and earlier are affected … |